Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
361
2024-10-18 10:05
reverse_ctl.exe
51dadf28bb2dfca8bcfdd80a15cfdfe1
Gen1
Generic Malware
Malicious Library
ASPack
UPX
Anti_VM
PE File
PE64
OS Processor Check
DLL
ZIP Format
VirusTotal
Malware
Check memory
Creates executable files
1.4
9
ZeroCERT
362
2024-10-18 10:03
taskhostws.exe
b47e4f366b08fe509c2a8f9ee7251f51
Generic Malware
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
IP Check
ComputerName
DNS
DDNS
1
Info
×
checkip.dyndns.org(132.226.8.169)
1
Info
×
ET INFO External IP Lookup Domain in DNS Query (checkip .dyndns .org)
4.0
26
ZeroCERT
363
2024-10-18 10:01
Swift-Stage1-Obfuscated.exe
0444eb9fbbf0d5ee3718acafd88e0843
Malicious Packer
UPX
PE File
PE64
VirusTotal
Malware
Checks debugger
3.2
M
51
ZeroCERT
364
2024-10-18 10:01
ywx.exe
4dba58c6e9f435c1cca607525760d0fd
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
AutoRuns
unpack itself
AppData folder
Windows
DNS
1
Info
×
176.111.174.140 - malware
5.6
M
49
ZeroCERT
365
2024-10-18 09:59
reddit.exe
23544090c6d379e3eca7343c4f05d4d2
Malicious Packer
UPX
PE File
PE32
VirusTotal
Malware
unpack itself
DNS
1
Info
×
147.185.221.23
3.6
M
61
ZeroCERT
366
2024-10-18 09:59
net.msi
5375c07cb8e6bedd4c3f26c9509d1562
Generic Malware
Malicious Library
Admin Tool (Sysinternals etc ...)
AntiDebug
AntiVM
MSOffice File
CAB
OS Processor Check
VirusTotal
Malware
suspicious privilege
Code Injection
Check memory
Checks debugger
unpack itself
AntiVM_Disk
VM Disk Size Check
ComputerName
crashed
3.8
M
26
ZeroCERT
367
2024-10-18 09:57
EGwnUqNrVeLFNPw.exe
6ed4c16533ca8aa8fff3708e4b5d321b
Generic Malware
Malicious Library
.NET framework(MSIL)
Antivirus
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
.NET EXE
PE32
VirusTotal
Malware
powershell
PDB
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
powershell.exe wrote
Check virtual network interfaces
suspicious process
WriteConsoleW
IP Check
Windows
ComputerName
DNS
Cryptographic key
DDNS
1
Info
×
checkip.dyndns.org(193.122.130.0)
1
Info
×
ET INFO External IP Lookup Domain in DNS Query (checkip .dyndns .org)
11.2
M
33
ZeroCERT
368
2024-10-18 09:56
THURSDAYYYYMPDW-constraints.vb...
f9c4326981028f9a6d08d989cea0b877
Generic Malware
Antivirus
Hide_URL
PowerShell
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
Check virtual network interfaces
suspicious process
WriteConsoleW
Windows
ComputerName
Cryptographic key
1
Info
×
raw.githubusercontent.com(185.199.108.133) - malware
6.2
9
ZeroCERT
369
2024-10-18 09:25
Bank Payment Confirmation Orde...
44e1f98dde09e0525d219f374608325a
Generic Malware
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
IP Check
ComputerName
DNS
DDNS
1
Info
×
checkip.dyndns.org(193.122.130.0)
1
Info
×
ET INFO External IP Lookup Domain in DNS Query (checkip .dyndns .org)
4.4
41
ZeroCERT
370
2024-10-17 16:51
bb.ps1
094bc518d9adb0f72eee6c727ec1cef7
Generic Malware
Antivirus
Lnk Format
GIF Format
VirusTotal
Malware
powershell
AutoRuns
MachineGuid
Check memory
Creates shortcut
Creates executable files
unpack itself
powershell.exe wrote
Check virtual network interfaces
WriteConsoleW
Windows
ComputerName
DNS
Cryptographic key
3
Keyword trend analysis
×
Info
×
http://157.173.104.153/up/bb.ps1
http://157.173.104.153/up/b.ps1
http://157.173.104.153/up/get-command.php
1
Info
×
157.173.104.153 - malware
5.8
M
9
ZeroCERT
371
2024-10-17 16:48
bd.ps1
2ab24d76a4372ba60974d6661e8d0325
Generic Malware
Antivirus
Lnk Format
GIF Format
VirusTotal
Malware
powershell
AutoRuns
MachineGuid
Check memory
Creates shortcut
Creates executable files
unpack itself
powershell.exe wrote
Check virtual network interfaces
WriteConsoleW
Windows
ComputerName
DNS
Cryptographic key
2
Keyword trend analysis
×
Info
×
http://157.173.104.153/up/get-command.php
http://157.173.104.153/up/b.ps1
1
Info
×
157.173.104.153 - malware
6.6
M
10
ZeroCERT
372
2024-10-17 16:46
b.ps1
633e79b5e535ec56f58696658967b9d3
Generic Malware
Antivirus
Check memory
unpack itself
Check virtual network interfaces
WriteConsoleW
Windows
ComputerName
DNS
Cryptographic key
1
Keyword trend analysis
×
Info
×
http://157.173.104.153/up/index.php
1
Info
×
157.173.104.153 - malware
4.8
M
ZeroCERT
373
2024-10-17 16:44
ChromePass.exe
a892c43b0cf244f070f97fafdb224cf4
Generic Malware
Malicious Library
UPX
PE File
PE32
Browser Info Stealer
VirusTotal
Malware
PDB
Browser
Remote Code Execution
2.0
M
51
ZeroCERT
374
2024-10-17 14:59
AppReseter_forOutlooker.exe
4c4200cdf2e58dee2b4db5200c231468
RedLine Infostealer
UltraVNC
Generic Malware
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
PDB
suspicious privilege
Check memory
Checks debugger
unpack itself
Windows
Cryptographic key
crashed
4.4
M
43
ZeroCERT
375
2024-10-17 14:58
crmdashboard.exe
563885497a6ff9f1a02361e43c16bd76
Malicious Library
.NET framework(MSIL)
UPX
PE File
.NET EXE
PE32
OS Processor Check
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
DNS
1
Info
×
3.78.28.71
2.6
M
61
ZeroCERT
First
Previous
21
22
23
24
25
26
27
28
29
30
Next
Last
Total : 49,341cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword